38 lines
1.4 KiB
Rust
38 lines
1.4 KiB
Rust
//! Tool usage patterns — detect dangerous or suspicious tool invocations.
|
|
|
|
/// Check whether a tool invocation matches a known dangerous pattern.
|
|
///
|
|
/// Returns a description of the risk if the pattern matches, or `None`
|
|
/// if the invocation appears safe.
|
|
pub fn check_dangerous_pattern(tool_name: &str, args: &serde_json::Value) -> Option<String> {
|
|
match tool_name {
|
|
"bash" => {
|
|
let cmd = args
|
|
.get("command")
|
|
.and_then(|v| v.as_str())
|
|
.unwrap_or("");
|
|
// Detect git push with --force
|
|
if cmd.contains("git push") && cmd.contains("--force") {
|
|
return Some("Force-pushing to git is destructive and may lose history".to_string());
|
|
}
|
|
// Detect rm -rf /
|
|
if cmd.contains("rm -rf /") || cmd.contains("rm -rf /*") {
|
|
return Some("Recursive deletion of the root filesystem is never allowed".to_string());
|
|
}
|
|
}
|
|
"delete" => {
|
|
let path = args
|
|
.get("path")
|
|
.and_then(|v| v.as_str())
|
|
.unwrap_or("");
|
|
if path == "/" || path.starts_with("/etc") {
|
|
return Some(format!("Deleting '{}' is too dangerous", path));
|
|
}
|
|
}
|
|
_ => {
|
|
tracing::debug!("no guard pattern registered for tool: {tool_name}");
|
|
}
|
|
}
|
|
None
|
|
}
|